9.8
CVSSv3

CVE-2021-43527

Published: 08/12/2021 Updated: 23/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

NSS (Network Security Services) versions before 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla nss esr

mozilla nss

netapp cloud backup -

netapp e-series santricity os controller

oracle communications cloud native core network slice selection function 1.8.0

oracle communications cloud native core network repository function 1.15.0

oracle communications cloud native core network repository function 1.15.1

oracle communications cloud native core binding support function 1.11.0

oracle communications policy management 12.6.0.0.0

starwindsoftware starwind virtual san v8r13

starwindsoftware starwind san \\& nas v8r13

Vendor Advisories

Synopsis Important: OpenShift Virtualization 4110 Images security and bug fix update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Virtualization release 4110 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a secur ...
Synopsis Important: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Important Topic An update for openshift-gitops-applicationset-container, openshift-gitops-container, openshift-gitops-kam-delivery-container, and openshift-gitops-operator-container is now available for Red Hat OpenShift GitOps 12 (GitOps v122)Re ...
Synopsis Important: OpenShift Container Platform 4110 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4110 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Co ...
Tavis Ormandy discovered that nss, the Mozilla Network Security Service library, is prone to a heap overflow flaw when verifying DSA or RSA-PPS signatures, which could result in denial of service or potentially the execution of arbitrary code For the oldstable distribution (buster), this problem has been fixed in version 2:3421-1+deb10u4 For th ...
NSS (Network Security Services) up to and including 373 is vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted Applications using NSS for certificate validation or other TLS, X509, OCSP or CRL ...
Mozilla Foundation Security Advisory 2021-51 Memory corruption in NSS via DER-encoded DSA and RSA-PSS signatures Announced December 1, 2021 Impact critical Products NSS Fixed in NSS 3681 ...
A remote code execution flaw was found in the way NSS verifies certificates This flaw allows an attacker posing as an SSL/TLS server to trigger this issue in a client application compiled with NSS when it tries to initiate an SSL/TLS connection Similarly, a server application compiled with NSS, which processes client certificates, can receive a ...
NSS (Network Security Services) up to and including 373 is vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted Applications using NSS for certificate validation or other TLS, X509, OCSP or CRL f ...
NSS (Network Security Services) up to and including 373 is vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted Applications using NSS for certificate validation or other TLS, X509, OCSP or CRL ...
NSS (Network Security Services) up to and including 373 is vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted Applications using NSS for certificate validation or other TLS, X509, OCSP or CRL f ...
NSS (Network Security Services) up to and including 373 is vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted Applications using NSS for certificate validation or other TLS, X509, OCSP or CRL f ...
NSS (Network Security Services) up to and including 373 is vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted Applications using NSS for certificate validation or other TLS, X509, OCSP or CRL f ...
NSS (Network Security Services) versions prior to 373 are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted Applications using NSS for certificate validation or other TLS, X509, OCSP or CRL fu ...
LTS-96 has been updated in the LTS channel to&nbsp;9604664208 (Platform Version:&nbsp;14268830) for most ChromeOS devices Want to know more about Long-term Support? Click&nbsp;here&nbsp;This update contains multiple Security fixes, including:1278608&nbsp;High&nbsp;&nbsp;CVE-2021-43527&nbsp;Security: CA certificate import exploitable with lar ...
LTS-96 has been updated in the LTS channel to&nbsp;9604664209 (Platform Version:&nbsp;14268840) for most ChromeOS devices Want to know more about Long-term Support? Click&nbsp;here&nbsp;This update contains multiple Security fixes, including:1316946&nbsp;High&nbsp;&nbsp;CVE-2022-1638&nbsp;[v8] Integer overflow leading to OOB/CHECK in icu_71: ...
ALAS-2022-223 Amazon Linux 2022 Security Advisory: ALAS-2022-223 Advisory Release Date: 2022-12-06 16:42 Pacific ...
NSS (Network Security Services) up to and including 373 is vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted Applications using NSS for certificate validation or other TLS, X509, OCSP or CRL ...
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS ...